Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

70 advisories

Loading
undici vulnerable to caching and replay of unsafe HTTP method responses Low
CVE-2026-85008 was published for undici (npm) Sep 29, 2026
MegaManSec Credited to MegaManSec, mcollina, and UlisesGascon mcollina mcollina
UlisesGascon UlisesGascon
Electron: Sandboxed preload code cache can be poisoned by a compromised renderer High
CVE-2026-102677 was published for electron (npm) Sep 29, 2026
varisys Credited to varisys
Alleysira Credited to Alleysira
libp2p: Gossipsub StrictSign accepts attacker-signed messages as a victim RSA peer ID High
CVE-2026-86038 was published for @libp2p/gossipsub (npm) Sep 17, 2026
Alleysira Credited to Alleysira
CKAN MCP Server: Cache-key canonicalization collision enables cache confusion / poisoning Moderate
CVE-2026-73846 was published for @aborruso/ckan-mcp-server (npm) Sep 3, 2026
Gal3m Credited to Gal3m and mrostamipoor mrostamipoor mrostamipoor
geo-chen Credited to geo-chen
Medplum: Improper Validation of Redirect URI in External Auth Callback allows Authorization Code Leakage High
CVE-2026-53728 was published for @medplum/core (npm) Aug 17, 2026
sAjibuu Credited to sAjibuu
Auth.js: OAuth state, nonce, and PKCE check cookies are not bound to the provider that created them Moderate
CVE-2026-73419 was published for @auth/core (npm) Jul 23, 2026
Nadav0077 Credited to Nadav0077
Hexix23 Credited to Hexix23, alan-agius4, and JeanMeche alan-agius4 alan-agius4
JeanMeche JeanMeche
Budibase: Chat-Link Handoff Identity Confusion (Same-Tenant Account-Link CSRF) High
GHSA-pvcr-8mvp-w8qr was published for @budibase/server (npm) Jul 24, 2026
hypnguyen1209 Credited to hypnguyen1209
Better Auth: Account takeover via pre-account hijacking on magic-link and email-OTP sign-in High
GHSA-qq9h-g4jm-xgf3 was published for better-auth (npm) Jul 24, 2026
n8n: Account Takeover via Unverified Email Claim in Token Exchange Embed Login High
GHSA-8342-988q-86cr was published for n8n (npm) Jul 22, 2026
hono: Body Limit Middleware can be bypassed on AWS Lambda by understating `Content-Length` Moderate
CVE-2026-54288 was published for hono (npm) Jun 16, 2026
Rootingg Credited to Rootingg and cookesan cookesan cookesan
widavies Credited to widavies
@better-auth/sso provider registration has server-side request forgery via unvalidated OIDC endpoints Critical
CVE-2026-53513 was published for @better-auth/sso (npm) Jul 7, 2026
vaadata-poyetont Credited to vaadata-poyetont
Better Auth: OAuth refresh-token replay via missing client authentication on oidc-provider and mcp plugins Critical
CVE-2026-53512 was published for better-auth (npm) Jul 7, 2026
subhanUmer Credited to subhanUmer
Better Auth has an account takeover issue via OAuth auto-link to unverified pre-registered email High
CVE-2026-53516 was published for better-auth (npm) Jul 7, 2026
avrmeduard Credited to avrmeduard
alan-agius4 Credited to alan-agius4, JeanMeche, and josephperrott JeanMeche JeanMeche
josephperrott josephperrott
OpenClaw: Trusted retry endpoint checks could match hostname prefixes High
GHSA-77q5-rr5v-x43q was published for openclaw (npm) Jul 2, 2026
ccy41928-del Credited to ccy41928-del
sigstore-js has Insufficient Verification of Data Authenticity Moderate
CVE-2026-48816 was published for @sigstore/verify (npm) Jul 1, 2026
1seal Credited to 1seal, Str1ckl4nd, and Zyy0530 Str1ckl4nd Str1ckl4nd
Zyy0530 Zyy0530
pnpm: Unsafe default behavior breaks integrity check Moderate
CVE-2026-50573 was published for pnpm (npm) Jun 26, 2026
aszx87410 Credited to aszx87410
purpshell Credited to purpshell and SheIITear SheIITear SheIITear
whrit Credited to whrit
amwhoi Credited to amwhoi
ProTip! Advisories are also available from the GraphQL API